SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 358 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 358

Single answerRemove any malicious access or persisting mechanisms

A Snowflake security engineer discovers that a contractor account was compromised and used to create several objects intended to maintain unauthorized access. Investigation shows the user created a new login-enabled user with a public key, granted that user a custom role with broad privileges, and assigned the role to another existing service user. The engineer has already disabled the compromised contractor account. What is the MOST effective next step to remove malicious access and persistence while minimizing disruption to legitimate workloads?

  1. A

    Drop the suspicious user, revoke the custom role from all grantees, and review/remove any grants made by that role or to that role

  2. B

    Rotate the password for the compromised contractor account and unlock the account so activity can be monitored

  3. C

    Suspend the warehouses used during the incident to prevent the attacker from reconnecting

  4. D

    Transfer ownership of the suspicious role to SECURITYADMIN and leave existing grants in place for later review

Show answer and explanation

Correct answer: A

Explanation

This question tests the candidate’s ability to eradicate persistence after a Snowflake compromise, not merely contain the initial account. In Snowflake, attackers can persist by creating users, assigning public keys for key-pair authentication, creating custom roles, and granting those roles to users or other roles. Effective remediation focuses on removing unauthorized principals and unwinding privilege inheritance. Practically, this means disabling or dropping suspicious users, reviewing role grants with commands such as SHOW GRANTS TO USER, SHOW GRANTS OF ROLE, and SHOW GRANTS TO ROLE, and revoking any unauthorized privileges or role assignments. Suspending warehouses or only rotating the original user’s credentials does not remove persisted identities or grants. Snowflake best practices for security operations emphasize least privilege, careful grant review, and prompt removal of unauthorized users, roles, and privileges after an incident.

  • A. Correct.

    Correct. The scenario describes persistence through a newly created user, a custom role, and downstream role grants. The most effective containment and eradication step is to remove the malicious principal and unwind the privilege chain: drop or disable the suspicious user, revoke the custom role from every user/role that received it, and inspect/revoke object and account-level privileges associated with that role. This directly removes the attacker’s access path and any persistence mechanism they established, which aligns with incident response best practices in Snowflake: disable or remove unauthorized identities, review grants, and clean up malicious role assignments.

  • B. Incorrect.

    Incorrect. Rotating the compromised contractor account password may be part of credential hygiene, but the account has already been disabled and the malicious persistence was created through additional users and role grants. Unlocking the compromised account would increase risk, not reduce it. This option addresses the original account but fails to eradicate the attacker’s newly established access paths.

  • C. Incorrect.

    Incorrect. Suspending warehouses can interrupt query execution, but it does not remove Snowflake identities, role grants, object privileges, or login capability. Attackers can still retain access through persisted users, keys, and roles even if compute is temporarily unavailable. This is a common misconception that compute controls are sufficient for identity-based compromise.

  • D. Incorrect.

    Incorrect. Changing ownership of the suspicious role may improve administrative control over the role, but leaving grants in place means the attacker’s privilege path can still exist through users or roles that already have the role. Ownership transfer is not the same as revocation or cleanup. It may be useful during investigation, but it is not the most effective immediate step for removing persistence.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam